GitLab CE/EE Authorization Bypass Vulnerability in Project Access Token Management

Vulnerability

A vulnerability exists in GitLab Community Edition and Enterprise Edition, affecting all versions from 18.9 prior to 18.10.7, 18.11 prior to 18.11.4, and 19.0 prior to 19.0.1. Under certain conditions, a blocked Project Access Token could improperly access private resources due to inadequate authorization enforcement.

Impact

Exploitation of this vulnerability could lead to unauthorized access to private resources by a blocked Project Access Token.

Remediation

Users can upgrade to GitLab versions 18.10.7, 18.11.4, or 19.0.1 to address this vulnerability.

Added: May 28, 2026, 9:27 AM
Updated: May 28, 2026, 9:27 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
8.7
remediation
7.7
relevance
9.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.